Cyber magazine August2026 | Page 100

DATA BREACHES
“ MCP governance also comes into play because you make sure that an agent is only talking to those SaaS apps that it’ s allowed to, rather than everything the person controlling the agent has access to.”
Ultimately, Mayank argues that AI security is only as good as the security of the underlying data it interacts with. This foundational layer requires rigid, native data controls, a strength he attributes directly to their work within the Snowflake ecosystem.“ Fundamentally, all of these things are acting on your data,” he observes.“ You have to make sure your data is properly governed. We’ re very proud of all the governance controls we have in Snowflake.” As a final line of defence against catastrophic errors or malicious takeovers, Mayank advocates for hardcoded administrative safety blocks, such as requiring multiple sign-offs for high-risk actions.
He adds:“ As an admin, you can pre-set up and say,‘ Hey, if someone’ s going to go delete this backup data over here, make sure you have at least two of us approving it. Then, if one of us gets hacked, you can still get blocked because chances are the second one is not hacked yet. It reduces the odds.”
Two approvers is the gold standard for Snowflake at the moment, but Mayank preempts that more may be needed in the future.
The convergence of builders and defenders Historically, enterprise security has been defined by a strict division of labour. The engineers who built systems
100 August 2026